CVE-2014-1492

The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
mozillanetwork_security_services
𝑥
≤ 3.15.5
mozillanetwork_security_services
3.2
mozillanetwork_security_services
3.2.1
mozillanetwork_security_services
3.3
mozillanetwork_security_services
3.3.1
mozillanetwork_security_services
3.3.2
mozillanetwork_security_services
3.4
mozillanetwork_security_services
3.4.1
mozillanetwork_security_services
3.4.2
mozillanetwork_security_services
3.5
mozillanetwork_security_services
3.6
mozillanetwork_security_services
3.6.1
mozillanetwork_security_services
3.7
mozillanetwork_security_services
3.7.1
mozillanetwork_security_services
3.7.2
mozillanetwork_security_services
3.7.3
mozillanetwork_security_services
3.7.5
mozillanetwork_security_services
3.7.7
mozillanetwork_security_services
3.8
mozillanetwork_security_services
3.9
mozillanetwork_security_services
3.11.2
mozillanetwork_security_services
3.11.3
mozillanetwork_security_services
3.11.4
mozillanetwork_security_services
3.11.5
mozillanetwork_security_services
3.12
mozillanetwork_security_services
3.12.1
mozillanetwork_security_services
3.12.2
mozillanetwork_security_services
3.12.3
mozillanetwork_security_services
3.12.3.1
mozillanetwork_security_services
3.12.3.2
mozillanetwork_security_services
3.12.4
mozillanetwork_security_services
3.12.5
mozillanetwork_security_services
3.12.6
mozillanetwork_security_services
3.12.7
mozillanetwork_security_services
3.12.8
mozillanetwork_security_services
3.12.9
mozillanetwork_security_services
3.12.10
mozillanetwork_security_services
3.12.11
mozillanetwork_security_services
3.14
mozillanetwork_security_services
3.14.1
mozillanetwork_security_services
3.14.2
mozillanetwork_security_services
3.14.3
mozillanetwork_security_services
3.14.4
mozillanetwork_security_services
3.14.5
mozillanetwork_security_services
3.15
mozillanetwork_security_services
3.15.1
mozillanetwork_security_services
3.15.2
mozillanetwork_security_services
3.15.3
mozillanetwork_security_services
3.15.3.1
mozillanetwork_security_services
3.15.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nss
bookworm
2:3.87.1-1
fixed
bullseye
2:3.61-1+deb11u3
fixed
bullseye (security)
2:3.61-1+deb11u4
fixed
sid
2:3.105-2
fixed
trixie
2:3.105-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
chromium-browser
lucid
not-affected
precise
not-affected
quantal
not-affected
saucy
not-affected
trusty
dne
firefox
lucid
ignored
precise
Fixed 29.0+build1-0ubuntu0.12.04.2
released
quantal
Fixed 29.0+build1-0ubuntu0.12.10.3
released
saucy
Fixed 29.0+build1-0ubuntu0.13.10.3
released
trusty
Fixed 29.0+build1-0ubuntu0.14.04.2
released
nss
lucid
Fixed 3.15.4-0ubuntu0.10.04.2
released
precise
Fixed 3.15.4-0ubuntu0.12.04.2
released
quantal
Fixed 3.15.4-0ubuntu0.12.10.2
released
saucy
Fixed 2:3.15.4-0ubuntu0.13.10.2
released
trusty
Fixed 2:3.15.4-1ubuntu7
released
oxide-qt
lucid
dne
precise
dne
quantal
dne
saucy
dne
trusty
dne
thunderbird
lucid
ignored
precise
not-affected
quantal
ignored
saucy
ignored
trusty
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
MozillaFirefox
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-devel
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-translations-common
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
MozillaFirefox-translations-other
suse enterprise desktop 15
52.7.3-1.35
fixed
suse enterprise sap 15
52.7.3-1.35
fixed
suse enterprise server 15
52.7.3-1.35
fixed
libfreebl3
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libfreebl3-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libfreebl3-hmac
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
libsoftokn3-hmac
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-certs
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-certs-32bit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-devel
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-sysinit
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
mozilla-nss-tools
suse enterprise desktop 15
3.36.1-1.7
fixed
suse enterprise desktop 15 SP1
3.41.1-3.13.1
fixed
suse enterprise sap 15
3.36.1-1.7
fixed
suse enterprise sap 15 SP1
3.41.1-3.13.1
fixed
suse enterprise server 15
3.36.1-1.7
fixed
suse enterprise server 15 SP1
3.41.1-3.13.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nspr
RHEL 6
0:4.10.6-1.el6_5
fixed
nspr-devel
RHEL 6
0:4.10.6-1.el6_5
fixed
nss
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2-2.el7_0
fixed
nss-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2-2.el7_0
fixed
nss-pkcs11-devel
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2-2.el7_0
fixed
nss-softokn
RHEL 7
0:3.16.2-1.el7_0
fixed
nss-softokn-devel
RHEL 7
0:3.16.2-1.el7_0
fixed
nss-softokn-freebl
RHEL 7
0:3.16.2-1.el7_0
fixed
nss-softokn-freebl-devel
RHEL 7
0:3.16.2-1.el7_0
fixed
nss-sysinit
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2-2.el7_0
fixed
nss-tools
RHEL 6
0:3.16.1-4.el6_5
fixed
RHEL 7
0:3.16.2-2.el7_0
fixed
nss-util
RHEL 6
0:3.16.1-1.el6_5
fixed
RHEL 7
0:3.16.2-1.el7_0
fixed
nss-util-devel
RHEL 6
0:3.16.1-1.el6_5
fixed
RHEL 7
0:3.16.2-1.el7_0
fixed
References